Choose from = (equals), != (not equals), like, and not
like. The like operator matches to substrings. For example, to see all the audit events for files created in the folder /user/joe/out, specify Source like /user/joe/out.

Use not like to filter out events based on a partial string match. For example, to show audit events for a set of IP addresses that start with the same sequence
172.39.109, you can specify IP Addressnot like172.39.109.

Type a field value in the value text field.

For example, to see the events listed for Navigator, enter Service Name=Navigator.

To specify an additional filter, click and define the new criteria.

Audit events show that match all filters (AND).

Click Apply.

A filter breadcrumb appears above the list of audit events and the list of events displays all events that match all the filter criteria.

If this documentation includes code, including but not limited to, code examples, Cloudera makes this available to you under the terms of the Apache License, Version 2.0, including any required
notices. A copy of the Apache License Version 2.0 can be found here.